Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2025-62709MEDIUMClipBucket v5 is vulnerable to password reset link manipulationEPSS 0.4%CVE-2025-50503HIGHA vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password meEPSS 0.4%CVE-2025-29995HIGHAccount Takeover Vulnerability in CAP back office applicationEPSS 0.4%CVE-2022-42807A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participaEPSS 0.4%CVE-2024-5277MEDIUMWeak Password Recovery Mechanism in lunary-ai/lunaryEPSS 0.4%CVE-2026-9466MEDIUMTiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recoveryEPSS 0.4%CVE-2025-14783MEDIUMEasy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirectEPSS 0.4%CVE-2025-2093LOWPHPGurukul Online Library Management System change-password.php password recoveryEPSS 0.4%CVE-2026-36438MEDIUMAn issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset fEPSS 0.3%CVE-2026-32103MEDIUMStudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link GenerationEPSS 0.3%CVE-2026-93453HIGHSOGo before 5.12.11 Password Reset Token Interception via Origin HeaderEPSS 0.3%CVE-2025-32486CRITICALWordPress Material Dashboard plugin <= 1.4.6 - Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-43932CRITICALJobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depeEPSS 0.3%CVE-2025-43931CRITICALflask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reEPSS 0.3%CVE-2025-64101HIGHZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header InjectionEPSS 0.3%CVE-2026-53904MEDIUMAccount Denial of Service in MCOEPSS 0.3%CVE-2026-12949CRITICALWishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' ParameterEPSS 0.3%CVE-2024-45670MEDIUMIBM Security SOAR weak password recovery mechanismEPSS 0.3%CVE-2026-61967CRITICALWordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerabilityEPSS 0.3%CVE-2026-72856HIGHBudibase before 3.40.0 Authentication Bypass via Tenant Owner EmailEPSS 0.3%